All compliance pages

Data Protection Policy

Last reviewed: Updated 2025

Operational rules and controls to prevent data leaks, unauthorized modifications, or privacy breaches.

DATA PROTECTION POLICY

Document Control
Document NameData Protection Policy
Reference No.DJTMPL/IT/POL/DPP
Policy OwnerChief Operation Officer
Policy Approving AuthorityBoard Of Directors
Version No.1.0
Document StatusDefinitive
Review Date01-04-2026
Compliance StatusMandatory
Next Review Period01-04-2027
Security ClassificationInternal Use Only
DistributionDJT MICROFINANCE PRIVATE LIMITED

Revision History

VersionDateChange Description
1.001-04-2026First version

Table Of Content

S. NoParticulars
1Abbreviations
2Terms and Definitions
3Purpose
4Scope
5Categories Of Personal Data Collected
6Purpose of Data Collection
7Notice and Disclosure to Data Principal
8Obtaining Consent
9Processing Of Personal Data
10Retention Of Personal Data
11Sharing Of Personal Data
12Data Security
13Rights Of Data Principal
14Data Principal Access Request
15Privacy by Design
16Governance And Accountability
17Policy Compliance

1. Abbreviations

AbbreviationFull Form
DPDP ActDigital Personal Data Protection Act, 2023
e-KYCElectronic Know Your Customer
KYCKnow Your Customer
MFIMicrofinance Institution
NBFCNon-Banking Financial Company
NDANon-Disclosure Agreement
OTPOne-Time Password
PIIPersonally Identifiable Information
RBIReserve Bank of India
UIDAIUnique Identification Authority of India
VIDVirtual ID

2. Terms and Definitions

TermDefinition
Aadhaar NumberIdentification number issued to an individual under Section 3 of the Aadhaar (Targeted Delivery of Financial and other Subsidies, Benefits and Services) Act, 2016, including any Virtual ID issued in lieu thereof.
AnonymizationIrreversible process of transforming personal data such that an individual cannot be identified from it.
ConsentFree, informed, specific, clear, and withdrawable affirmative action given by the Data Principal before processing of their personal data.
Data FiduciaryDJT Microfinance PVT. LTD., as the entity that determines the purpose and means of processing personal data.
Data PrincipalThe individual whose personal data is being collected or processed (e.g., customer, borrower).
De-identificationProcess of removing or masking identifiers from personal data so that the individual cannot be directly identified.
Personal DataData about or relating to a natural person who is directly or indirectly identifiable, including any inference drawn for profiling.
ProcessingAny operation on personal data — collection, storage, use, sharing, transfer, erasure, or destruction.
Sensitive Personal DataIncludes financial information (bank account, credit/debit card), biometric information, health data, and Aadhaar-related identity information.
Virtual ID (VID)An alternative virtual identity issued as a substitute for the Aadhaar number for authentication purposes.

3. Purpose

The purpose of this policy is to provide clear direction to all employees, management, and relevant stakeholders of DJT Microfinance PVT. LTD. on the collection, use, storage, sharing, and disposal of personal data — particularly in the context of:

    • Compliance with the Digital Personal Data Protection (DPDP) Act, 2023
    • Compliance with RBI guidelines on KYC / e-KYC for NBFCs and Microfinance Institutions
    • Compliance with the Aadhaar Act, 2016, its amendments, and UIDAI regulations
    • Alignment with Companies Act, 2013 obligations on data governance and fiduciary duties
    • Protection of customer and employee personal data from unauthorized access, misuse, or breach

DJTMPL, in the conduct of its microfinance business, collects sensitive personal and financial data from customers, employees, and business partners. This policy ensures that such data is handled responsibly, lawfully, and transparently.

4. Scope

This policy applies to:

    • All employees of DJTMPL (permanent, contractual, and temporary)
    • All third-party service providers, agents, and vendors with access to DJTMPL data
    • All forms of personal data — whether in physical (paper) or digital (electronic) format
    • All systems, applications, and databases used to collect, process, or store personal data

Personal data in scope includes — but is not limited to — customer KYC data, Aadhaar-based identity information, financial records, loan account data, employee records, and any other data that can identify an individual.

5. Categories of Personal Data Collected

DJTMPL collects only the minimum data necessary for lawful business purposes. The following categories of data are collected:

CategoryExamplesProtection Level
Customer IdentityName, address, date of birth, photographHigh
Financial DataBank account, loan details, repayment historyHigh
KYC / e-KYC DataAadhaar number / VID, PAN, Voter ID, PassportCritical
Biometric DataFingerprint, iris scan (used for Aadhaar authentication)Critical
Contact InformationMobile number, email address, mailing addressMedium
Employment / IncomeEmployer details, income proof, salary slipsHigh
Internal RecordsLoan files, audit logs, board resolutionsMedium

Data collection shall be limited to what is necessary for the specific, stated purpose (principle of data minimization). Aadhaar numbers shall only be collected where explicitly permitted under the Aadhaar Act 2016 and RBI KYC Master Direction.

6. Purpose of Data Collection

Personal data shall only be collected and processed for the following legitimate purposes:

    • Customer onboarding and KYC verification as mandated under RBI KYC Master Direction
    • e-KYC authentication via UIDAI for account opening and loan processing
    • Loan appraisal, disbursement, and repayment tracking
    • Compliance with Anti-Money Laundering (AML) and PMLA obligations
    • Credit bureau reporting as required by RBI
    • Customer service, grievance handling, and complaint resolution
    • Regulatory reporting to RBI, NABARD, or other statutory authorities
    • Internal audit, risk management, and legal proceedings

Personal data shall not be used beyond the purpose for which it was collected. Any new use of existing data shall require a fresh notice to, and consent from, the data principal, unless otherwise exempted under applicable law.

7. Notice and Disclosure to Data Principal

Prior to collecting personal data, DJTMPL shall provide the following information to each data principal (customer/individual) in clear and simple language:

    • The purpose for which personal data / identity information is being collected
    • The types of data being collected and how they will be used
    • Whether submission of Aadhaar number is mandatory or voluntary, and the legal provision mandating it, if applicable
    • Alternatives to Aadhaar-based identification where available (e.g., PAN, Passport, Voter ID)
    • The right to use Virtual ID (VID) in lieu of Aadhaar number for authentication
    • Details of the Privacy Officer and contact information for queries or complaints
    • That the data principal has the right to withdraw consent and the process for doing so

Authentication notifications: The data principal shall be notified via SMS or email at the time of Aadhaar authentication. DJTMPL shall maintain logs of all such notifications.

DJTMPL shall obtain explicit, informed, and recorded consent from the data principal before collecting and processing their personal data. The following conditions apply:

    • Consent shall be free, specific, informed, clear, and withdrawable
    • Consent shall be obtained in writing or in electronic form (on DJTMPL application, website, or system)
    • For sensitive personal data (including Aadhaar and financial information), explicit consent shall be obtained separately
    • DJTMPL shall maintain logs of consent, including the information disclosed and the date and method of consent
    • The Legal / Compliance team shall vet the consent mechanism and formally approve it
    • Consent shall not be bundled as a pre-condition for providing services unless the data is strictly necessary for that service
    • Data principals may withdraw consent at any time; DJTMPL shall provide a simple and accessible mechanism for withdrawal

9. Processing of Personal Data

Personal data collected by DJTMPL shall be processed in compliance with applicable law and only for the purposes for which it was collected. The following principles govern all processing activities:

9.1 Aadhaar / e-KYC Data

    • Aadhaar number / VID, biometric, and demographic data collected during e-KYC shall only be used for UIDAI authentication
    • DJTMPL shall not use Aadhaar data for any purpose beyond what is permitted under RBI Master Direction DBR.AML.BC.No.81/14.01.001/2015-16
    • Demographic details received from UIDAI shall be used only for customer identification for the specific service and duration of the service
    • DJTMPL has been classified as a Local AUA by UIDAI and shall not store Aadhaar numbers in its systems — only UID Tokens shall be stored

9.2 General Processing Principles

    • Lawfulness — all processing shall have a legal basis (consent, contract, legal obligation, or legitimate interest)
    • Purpose limitation — data shall be used only for the stated purpose
    • Data minimization — only the minimum data necessary shall be collected
    • Accuracy — data shall be kept accurate and up to date
    • Storage limitation — data shall not be retained longer than necessary
    • Security — appropriate technical and organisational measures shall protect data

10. Retention of Personal Data

DJTMPL shall retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law, whichever is later.

Data CategoryRetention PeriodLegal Basis
KYC Records (physical & digital)5 years after account closureRBI KYC Master Direction
Authentication / e-KYC Transaction Logs2 years activeUIDAI / Aadhaar (Data Security) Regs, 2016
Loan Account Records8 years post loan closurePMLA, 2002
Employee RecordsDuration of employment + 5 yearsCompanies Act, 2013 / Labour laws

Upon expiry of the retention period, personal data shall be securely deleted or anonymized unless retention is required by a court order or pending legal proceeding.

11. Sharing of Personal Data

DJTMPL shall not share personal data with third parties except in the following circumstances:

    • As required by RBI, NABARD, SEBI, or other regulatory / statutory authorities
    • As required for credit bureau reporting (CIBIL, Equifax, CRIF, Experian) per RBI mandate
    • With service providers engaged under a formal contract with confidentiality and data protection obligations (NDA / DPA)
    • With collection agencies or legal counsel in the course of lawful debt recovery
    • With auditors and regulators for compliance and inspection purposes
    • With the explicit, recorded consent of the data principal for any other purpose

Sharing Restrictions:

    • Biometric information shall not be transmitted over any network without encryption and PID block creation as required under Aadhaar Act
    • Aadhaar numbers shall not be transmitted over the internet unless via a secure, encrypted channel
    • Identity information shall not be shared in contravention of the Aadhaar Act or UIDAI circulars
    • Identity information shall not be hosted or transferred outside the territory of India

12. Data Security

DJTMPL shall implement appropriate technical and organizational measures to protect personal data from unauthorized access, loss, misuse, or breach. These include:

12.1 Technical Controls

    • All Aadhaar/KYC data shall be collected over a secure application and transmitted over encrypted channels as per UIDAI specifications
    • e-KYC data shall be stored in encrypted form compliant with UIDAI encryption standards
    • Biometric devices used for Aadhaar authentication shall be STQC/UIDAI certified
    • OTP collected for authentication shall be encrypted at the device level before transmission
    • Access to authentication applications, audit logs, and source code shall be restricted to authorized personnel only
    • An Access Control List (ACL) shall be maintained and reviewed regularly
    • Aadhaar numbers, where applicable, shall be stored only in Aadhaar Data Vault (ADV) per UIDAI specifications

12.2 Organizational Controls

    • All applications used for Aadhaar authentication or e-KYC shall be tested for compliance annually by STQC/CERT-IN certified auditors
    • NDAs shall be in place for all employees, contractors, consultants, and agencies handling personal data
    • Staff involved in KYC / Aadhaar processing shall be trained on data privacy obligations on a periodic basis
    • An Information Security Policy aligned with ISO 27001 and the DPDP Act shall be maintained
    • Best practices in data privacy and protection based on international standards shall be adopted

12.3 Breach Notification

In the event of a personal data / identity information breach, DJTMPL shall:

    • Notify the relevant authority (UIDAI / CERT-IN / RBI as applicable) with: a description and consequences of the breach, number of individuals affected, measures taken to mitigate the breach, and the Privacy Officer's contact details
    • Notify affected data principals as required under the DPDP Act, 2023
    • Document the breach, investigation findings, and remediation steps

13. Rights of Data Principals

Under the DPDP Act, 2023 and applicable regulations, data principals (customers / individuals) have the following rights:

RightDescription & DJTMPL's Obligation
Right to InformationData principal may request information about what personal data DJTMPL holds about them and how it is being used
Right to CorrectionData principal may request correction or update of inaccurate / incomplete personal data. Where updates require UIDAI verification, the data principal shall be informed accordingly
Right to ErasureData principal may request deletion of their personal data where no longer necessary. Core biometric data is protected under Section 29 of the Aadhaar Act and cannot be returned or deleted on request
Right to Withdraw ConsentData principal may withdraw consent for processing at any time. DJTMPL shall delete the relevant e-KYC data in a verifiable manner and provide written acknowledgement
Right to Grievance RedressalData principal may lodge a complaint with the Privacy Officer. If unresolved, the data principal may seek redressal under Section 33B of the Aadhaar Act, 2016 or under DPDP Act mechanisms

14. Data Principal Access Requests

DJTMPL shall establish and maintain a formal process for handling data principal requests:

    • All requests shall be formally recorded and acknowledged within 3 working days
    • Identity of the data principal shall be verified before providing access to any personal data
    • Requests shall be responded to within a reasonable period as prescribed under applicable law
    • Compliance with the relevant data protection and privacy laws shall be ensured for all requests
    • A dedicated channel (email / helpdesk) shall be made available for data principal requests

15. Privacy by Design

DJTMPL shall embed data privacy principles at the design stage of any new system, product, process, or technology involving personal data processing. This includes:

    • Conducting a Privacy Impact Assessment (PIA) before launching any new data processing activity
    • Ensuring disclosure / consent mechanisms are in place before going live with any new process
    • Implementing anonymization, de-identification, and data minimization wherever feasible
    • Ensuring that Aadhaar numbers are not published or exposed in any database or report — they must be redacted or blacked out in print and electronic form
    • Conducting quarterly self-assessments to ensure ongoing compliance with disclosure of information and consent requirements

16. Governance and Accountability

16.1 Privacy Officer

DJTMPL shall designate a Privacy Officer (Data Protection Officer) responsible for:

DetailInformation
DesignationPrivacy / Data Protection Officer
Reporting ToChief Information Officer / CISO
Key Responsibilities
    • Oversee compliance with DPDP Act 2023 and RBI guidelines
    • Manage data subject access and consent requests
    • Conduct quarterly privacy self-assessments
    • Coordinate CERT-IN / UIDAI-notifiable breach reporting
    • Maintain and communicate this policy to all stakeholders

16.2 Privacy Committee

A Privacy Committee shall be established to provide strategic direction on privacy matters. The committee shall include representation from IT, Legal/Compliance, Operations, and Senior Management.

16.3 Board-Level Accountability

In accordance with the Companies Act, 2013, the Board of Directors of DJTMPL bears fiduciary responsibility for data governance. The Board shall:

    • Approve and periodically review this Data Protection Policy
    • Ensure adequate resources are allocated for data protection compliance
    • Receive periodic reports on the status of data protection compliance and any material incidents

16.4 Implementation Responsibility

ResponsibilityRole / Designation
Policy Monitoring & EnforcementChief Audit Officer
Controls ImplementationChief Business Officer
Consent & Disclosure ReviewChief Business Officer / Legal Head
IT / Technical ControlsGroup IT Head
Policy CommunicationPrivacy Officer / HR Head

17. Policy Compliance

17.1 Compliance Measurement

The Infosec / Compliance team shall verify adherence to this policy through internal audits, system reviews, and regulatory inspection readiness checks. The Privacy Officer shall conduct quarterly self-assessments and present findings to the Privacy Committee.

17.2 Exceptions

Requests for exceptions must have a documented business justification and associated risk assessment. Exceptions must be approved by the Group IT Head and Top Management, are time-bound, and shall be re-evaluated upon expiry.